EP2973176A4 - System and method employing structured intelligence to verify and contain threats at endpoints - Google Patents

System and method employing structured intelligence to verify and contain threats at endpoints

Info

Publication number
EP2973176A4
EP2973176A4 EP14762444.9A EP14762444A EP2973176A4 EP 2973176 A4 EP2973176 A4 EP 2973176A4 EP 14762444 A EP14762444 A EP 14762444A EP 2973176 A4 EP2973176 A4 EP 2973176A4
Authority
EP
European Patent Office
Prior art keywords
endpoints
verify
method employing
employing structured
intelligence
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP14762444.9A
Other languages
German (de)
French (fr)
Other versions
EP2973176A1 (en
Inventor
Sean Cunningham
Robert Dana
Joseph Nardone
Joseph Faber
Kevin Arunski
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Mandiant LLC
Original Assignee
Mandiant LLC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mandiant LLC filed Critical Mandiant LLC
Priority claimed from PCT/US2014/030633 external-priority patent/WO2014145805A1/en
Publication of EP2973176A1 publication Critical patent/EP2973176A1/en
Publication of EP2973176A4 publication Critical patent/EP2973176A4/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/128Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Virology (AREA)
  • General Health & Medical Sciences (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer And Data Communications (AREA)
EP14762444.9A 2013-03-15 2014-03-17 System and method employing structured intelligence to verify and contain threats at endpoints Pending EP2973176A4 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US201361800796P 2013-03-15 2013-03-15
PCT/US2014/030633 WO2014145805A1 (en) 2013-03-15 2014-03-17 System and method employing structured intelligence to verify and contain threats at endpoints

Publications (2)

Publication Number Publication Date
EP2973176A1 EP2973176A1 (en) 2016-01-20
EP2973176A4 true EP2973176A4 (en) 2016-11-23

Family

ID=54842942

Family Applications (1)

Application Number Title Priority Date Filing Date
EP14762444.9A Pending EP2973176A4 (en) 2013-03-15 2014-03-17 System and method employing structured intelligence to verify and contain threats at endpoints

Country Status (1)

Country Link
EP (1) EP2973176A4 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100077481A1 (en) * 2008-09-22 2010-03-25 Microsoft Corporation Collecting and analyzing malware data
US20110173699A1 (en) * 2010-01-13 2011-07-14 Igal Figlin Network intrusion detection with distributed correlation
US20120233696A1 (en) * 2011-03-09 2012-09-13 Beijing Netqin Technology Co., Ltd. Method and system for antivirus by sim card combined with cloud computing

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100077481A1 (en) * 2008-09-22 2010-03-25 Microsoft Corporation Collecting and analyzing malware data
US20110173699A1 (en) * 2010-01-13 2011-07-14 Igal Figlin Network intrusion detection with distributed correlation
US20120233696A1 (en) * 2011-03-09 2012-09-13 Beijing Netqin Technology Co., Ltd. Method and system for antivirus by sim card combined with cloud computing

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
JON OBERHEIDE ET AL: "CloudAV: N-Version Antivirus in the Network Cloud", USENIX,, 15 July 2008 (2008-07-15), pages 1 - 16, XP061009236 *
KHALED SALAH ET AL: "Using Cloud Computing to Implement a Security Overlay Network", SECURITY & PRIVACY, IEEE, IEEE SERVICE CENTER, LOS ALAMITOS, CA, US, vol. 11, no. 1, 1 January 2013 (2013-01-01), pages 44 - 53, XP011492898, ISSN: 1540-7993, DOI: 10.1109/MSP.2012.88 *
See also references of WO2014145805A1 *
VLADIMIR GETOV: "Security as a Service in Smart Clouds -- Opportunities and Concerns", COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), 2012 IEEE 36TH ANNUAL, IEEE, 16 July 2012 (2012-07-16), pages 373 - 379, XP032472770, ISBN: 978-1-4673-1990-4, DOI: 10.1109/COMPSAC.2012.112 *

Also Published As

Publication number Publication date
EP2973176A1 (en) 2016-01-20

Similar Documents

Publication Publication Date Title
GB2533520B (en) Gaze-controlled interface method and system
HUE061173T2 (en) Application method and application system
EP2943922A4 (en) System and method for enhanced commerce
GB2526499B (en) Irrigation system and method
EP2966746A4 (en) Energy management system and energy management method
IL268409A (en) Structure assembly system and method
SG10201400368XA (en) Image-Domain 4D-Binning Method And System
GB2535673B (en) Group communication method and system
EP3086504A4 (en) Authentication system and authentication method
IL227627A0 (en) Georefenrencing method and system
EP3058665A4 (en) Communication method and system
EP2992272A4 (en) Energy recovery system and method
GB201420486D0 (en) Injection system and method
EP3086252A4 (en) Authentication system and authentication method
EP2964917A4 (en) Method pertaining to an scr system and an scr system
EP2967406A4 (en) Method and system to calculate qeeg
GB201305411D0 (en) System and method
PL3071918T3 (en) Method for direction limitation and system for direction limitation
GB201316831D0 (en) Security System and Method
IL243085B (en) System and method for irrigation
EP3082057A4 (en) Authentication method and authentication system
HK1223187A1 (en) A method and system to improve reading
SG11201602344XA (en) Mast system and method
GB201515529D0 (en) Injector and method
EP2983835A4 (en) Coating system and method

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20151015

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

DAX Request for extension of the european patent (deleted)
A4 Supplementary search report drawn up and despatched

Effective date: 20161021

RIC1 Information provided on ipc code assigned before grant

Ipc: G06F 21/56 20130101AFI20161017BHEP

Ipc: H04L 29/06 20060101ALI20161017BHEP

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS

17Q First examination report despatched

Effective date: 20190225

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS